Exploitation Summary
EIP tracks 2 public exploits for CVE-2024-28741.
PoCs published by chebuya, h00die, chebuya, including Metasploit module exploits/windows/http/northstar_c2_xss_to_agent_rce.
AI-analyzed exploit summary This PoC exploits CVE-2024-28741, a stored XSS vulnerability in NorthStar C2, by sending multiple malicious agent registration requests to build a JavaScript payload in the logs web page, enabling remote command execution on NorthStar C2 agents.
Description
Cross Site Scripting vulnerability in EginDemirbilek NorthStar C2 v1 allows a remote attacker to execute arbitrary code via the login.php component.
Exploits (2)
This PoC exploits CVE-2024-28741, a stored XSS vulnerability in NorthStar C2, by sending multiple malicious agent registration requests to build a JavaScript payload in the logs web page, enabling remote command execution on NorthStar C2 agents.
This Metasploit module exploits a stored XSS vulnerability in NorthStar C2 (CVE-2024-28741) to achieve unauthenticated session hijacking and subsequent remote code execution on compromised agents. The exploit chains XSS with agent command execution to run arbitrary payloads.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H